AI SIEM

Ingestion pipeline · normalized schema · hot / warm / cold storage

Total events / day
107.4B
+6.1%
Hot tier used
184 TB
of 500 TB
Retention
400 days
hot 30 · warm 90 · cold 280
Parse success
99.94%
+0.02%

Query editor

AegisQL · natural language or KQL-compatible

source=okta.system | where risk.level == "high"
| join (source=crowdstrike.edr | where verdict=="quarantine") on user.email
| stats count() by user.email, geo.country
| sort -count | limit 25
Scanned 4.8B events in 712ms·17 rows·Est. cost 0.004 credits

Ingest vs. parse throughput

k EPS · last 30 min

Parsers

Schema mapping health

  • AWS CloudTrail JSON
    384k EPS · v4.2
    healthy
  • CrowdStrike NDJSON
    212k EPS · v3.9
    healthy
  • Okta System Log
    48k EPS · v2.7
    healthy
  • Zscaler NSS
    176k EPS · v5.1
    healthy
  • Palo Alto Syslog CEF
    312k EPS · v6.0
    degraded

Log stream

Live normalized events · click a row to pivot into investigation

TimestampSourceActorActionAssetIPVerdict
14:22:03.417aws.cloudtrailarn:aws:iam::847::user/dev-clis3:GetObjects3://cust-data-prod54.212.83.9allow
14:22:03.301okta.systemdiane.k@fintech.iouser.session.startOkta portal185.212.98.14risky
14:22:02.882crowdstrike.edrSYSTEMprocess.exec powershell.exe -encMKT-LAP-04110.4.11.23quarantine
14:22:02.771zscaler.webpriya.s@corp.iohttp.getdns://update-server[.]tk10.4.7.88block
14:22:02.510gsuite.auditbilling@corp.iodrive.share.externalQ3-revenue.xlsx10.4.9.14review
14:22:02.114paloalto.pan-threat.spyware.blocked10.4.1.44185.199.108.153block
14:22:01.973aws.guardduty-recon.ec2.portscani-07f8ab...45.61.184.22alert